CVE Vulnerabilities

CVE-2016-3176

Improper Authentication

Published: Jan 31, 2017 | Modified: Feb 07, 2017
CVSS 3.x
5.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
HIGH

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack * 2015.5.9 (including)
Salt Saltstack 2015.8.0 (including) 2015.8.0 (including)
Salt Saltstack 2015.8.1 (including) 2015.8.1 (including)
Salt Saltstack 2015.8.2 (including) 2015.8.2 (including)
Salt Saltstack 2015.8.3 (including) 2015.8.3 (including)
Salt Saltstack 2015.8.4 (including) 2015.8.4 (including)
Salt Saltstack 2015.8.5 (including) 2015.8.5 (including)
Salt Saltstack 2015.8.7 (including) 2015.8.7 (including)
Salt Ubuntu esm-infra-legacy/trusty *
Salt Ubuntu trusty *
Salt Ubuntu trusty/esm *
Salt Ubuntu upstream *
Salt Ubuntu wily *

Potential Mitigations

References